在自动驾驶中,用光学镜片物理干扰单目深度估计,误导车辆判断距离。
Optical Lens Attack on Monocular Depth Estimation for Autonomous Driving
- 通过凹凸透镜改变摄像头成像,制造虚假深度感知。
- 在真实车辆和CARLA仿真中,攻击使深度估计误差超50%。
- 揭示了自动驾驶视觉系统的物理安全漏洞,适合关注安全性研究者。
单目深度估计(MDE)是基于视觉的自动驾驶(AD)系统的核心组件,使车辆能仅凭单张图像估算周围物体的距离,从而支持刹车、变道等关键决策。本文探讨了MDE算法在自动驾驶系统中的漏洞,提出一种名为LensAttack的新物理攻击方法:在自动驾驶车辆摄像头前放置光学透镜,以操控物体的深度感知。LensAttack包含两种攻击形式——凹透镜攻击和凸透镜攻击,分别利用不同类型的透镜诱导错误深度感知。我们首先建立攻击参数的数学模型,随后通过仿真与实车测试评估其对前沿MDE模型的攻击效果。此外,采用攻击优化方法进一步提升成功率,通过优化透镜焦距增强攻击效能。为更全面评估其对自动驾驶的影响,我们在CARLA平台上进行端到端系统仿真。结果表明,LensAttack可显著干扰深度估计过程,严重威胁系统的可靠性与安全性。最后,我们讨论了几种潜在的防御策略以缓解该攻击影响。
原文摘要 · Abstract (English)
Monocular Depth Estimation (MDE) is a pivotal component of vision-based Autonomous Driving (AD) systems, enabling vehicles to estimate the depth of surrounding objects using a single camera image. This estimation guides essential driving decisions, such as braking before an obstacle or changing lanes to avoid collisions. In this paper, we explore vulnerabilities of MDE algorithms in AD systems, presenting LensAttack, a novel physical attack that strategically places optical lenses on the camera of an autonomous vehicle to manipulate the perceived object depths. LensAttack encompasses two attack formats: concave lens attack and convex lens attack, each utilizing different optical lenses to induce false depth perception. We first develop a mathematical model that outlines the parameters of the attack, followed by simulations and real-world evaluations to assess its efficacy on state-of-the-art MDE models. Additionally, we adopt an attack optimization method to further enhance the attack success rate by optimizing the attack focal length. To better evaluate the implications of LensAttack on AD, we conduct comprehensive end-to-end system simulations using the CARLA platform. The results reveal that LensAttack can significantly disrupt the depth estimation processes in AD systems, posing a serious threat to their reliability and safety. Finally, we discuss some potential defense methods to mitigate the effects of the proposed attack.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。